15 ms·
Wirecard hired actors to fool auditors
- grenoire 6y agoCan we get an English report, preferably not paywalled? From what I can read in the first few paragraphs, the title seems sensationalised.
- ludamad 6y agoTo me it was implied someone hadn't written one yet, and hitting translate got me half the article. Admittedly, this leaves me half-informed
- gravitas 6y agoThe website is user-hostile; if you accept the Advertisements it attempts to set a cookie which the Firefox tracking protection layer won't allow to happen, resulting in an error and no article access.
- MichaelApproved 6y agoIs that FF tracking protection turned on by default?
- marcosdumay 6y agoYes, it's on by default. There is a site-wide off switch if you know where to look, but I doubt most people would find it.
- bzb4 6y agoOf course, if your browser is not standards compliant (no cookies) then you have to expect websites not to work.
- alpaca128 6y agoIf a simple news article cannot be displayed without cookies, scripts or CSS the failure is not on the client side. Something went seriously wrong if a beginner with 15 minutes of HTML experience can create a better performing, more usable site imho.
- bzb4 6y agoJournalists have bills to pay.
- natch 6y agoIs having bills to pay a valid excuse for any and all bad behavior?
- liability 6y agoIn the movie Thank You For Smoking a tobacco industry spokesman calls it the 'Yuppie Nuremberg Defense.' Instead of "I had orders" it's "I had a mortgage."
- alpaca128 6y agoBoth paywalls and ads are possible without any cookies, scripts or tracking.
- jacquesm 6y agoThat website wasn't made by journalists, but by their bosses. If the news is going to be 'for pay' only then effectively being informed equates to being wealthy and the not so wealthy will be preyed on by the 'fake news' department, because to them spreading the news is the business. So there is a very strong case to be made for keeping news free for the masses, even when they run adblockers.
- MaxBarraclough 6y agoFire up a Private Browsing session and let it install whatever cookies it likes. Not that this option makes it any less user-hostile.
- ludamad 6y agoAuditing - be it corporate accounting or election results - breeds false security the moment it doesn't work. I think transparency into critical vetting will be a big societal improvement.
- jacquesm 6y agoI do this for a living and if there is one thing that I have found it is that due to COVID-19 on-site visits are no longer an option (especially not internationally) and this has caused us to be blind to certain classes of problems. It is a lot of work to get around that remotely and to not have a drop in quality because of that. We are at least aware of the problem but even then this is a tricky thing to solve. When looking through a keyhole you can get a completely different view of a company than the one you get when you spend a day on their premises.
- fedreserved 6y agoOn other forums people are taking advantage of the situation to refinance their homes where they don't want a privacy inspection (medical marijuana grows which are legal, but under certain circumstances banks may ask questions)
- ludamad 6y agoBeyond your fair points, my statement is unfair because it's trivially true. "Transparency into critical vetting" hides the complexity of individual comprehension, single points of failure, etc. I just know I have very little trust into opaque processes that randomly blow up
- Tepix 6y agoWhat's the headhunter bounty for former Wirecard COO Jan Marsalek? He's still at large: https://www.finextra.com/newsarticle/36396/marsalek-joins-interpols-most-wanted-ranks https://www.finextra.com/newsarticle/36396/marsalek-joins-in...
- brian_herman__ 6y ago50 million woolongs?
- jacquesm 6y agohttps://www.bellingcat.com/news/uk-and-europe/2020/07/18/worlds-most-wanted-man-jan-marsalek-located-in-belarus-data-points-to-russian-intel-links/ https://www.bellingcat.com/news/uk-and-europe/2020/07/18/wor... Not sure how reliable that is but it would make some sense, close by and hard to impossible to be extradited from there.
- MiroF 6y agoIt's ridiculous how any rich person accused of fraud in the West can take asylum in Russia/China and vice versa.
- jacquesm 6y agoPecunia non olet is now about 2000 years old, not much has changed in that time.
- LargoLasskhyfv 6y agoThat may be true when it comes fresh from the ATM, but otherwise is mostly false. People physically handling money would tell you that it indeed STINKS!
- microtherion 6y agoDon't forget that the phrase was coined by an emperor who started charging for access to public latrines…
- KingOfCoders 6y agoAs the person responsible for IT I was audited in several companies by several of the large auditing firms. The people auditing IT had no clue what they were doing, no clue about IT and were just running a checklist. I could have told them whatever I liked.
- jacquesm 6y agoYes, we hear this all the time. It's just kids with checklists who have absolutely no idea about the nature of the questions they are asking, why they are asking them and have absolutely no plan for off-script follow up questions based on the answers given. A lot of these auditors come from a financial background and they treat IT in much the same way, as if there is some kind of checksum they can calculate which will tell them if the company is healthy from an IT perspective or not. Companies that are certified tend to be very good at process but are sometimes surprisingly bad at the actual IT. But it's all documented perfectly.
- exhilaration 6y agoSimilarly, I remember at my last job management would start talking about the "ISO corner" each year, where all the forms that we never, ever touched sat. This of course coincided with our ISO 9001 recertification. A few developers would be coached on what to say to the certifier, he'd be there for 2 days, and then we'd go back to business as usual.
- juskrey 6y ago
- jacquesm 6y agoHere's my little Wirecard story: Back in the day when Camarades.com/ww.com was doing well we were through an intermediary approached by a German investor, one Paul Bauer-Schlichtegroll (I'll never forget that name), an - at that moment - successful German businessman, who was importing Vans sports shoes into Europe. He became a 5% investor in our company through an entity called Max Madhouse GMBH with an option to buy a much larger share. The day after the deal was signed he turned around and tried to screw us - the founders - out of our own company through a minority shareholder lawsuit. Eventually we got rid of him, but this cost us a lot of time, money and momentum. Two years later Bauer was one of the founding members of what eventually became Wirecard. So I've always seen Wirecard as a bunch of crooks. At the same time I have some sympathy for the BaFin people, there are way too few of them and the opposition was very well versed in showing one face whilst actually being something completely different, the length to which these characters would go to show a good face was beyond anything that I would have normally imagined. I'm still a touch paranoid because of it, and I'm sure the same goes for the rest of the former Camarades.com/ww.com team. I don't know what happened to him, he seems to have disappeared as well, but I do know that anything that he's ever touched was rotten at some level.
- StreamBright 6y agoI can also add some here. We worked for WD for a while. There was this weird thing going on. We requested MacBooks because we were working on Linux and cloud but the management had a policy that managers were entitled to have MacBooks while by default engineers had to use Windows laptops. As externals we were denied MacBooks. So managers were running Powerpoints on Apple while engineers were running Python, aws-cli on Windows. Perfectly reasonable according to them. I could only estimate the amount of productivity lost on this. Of course WSL was not allowed because corporate security classified it insecure.
- spiritplumber 6y agoHow did you guys solve it?
- 6y ago
- pvitz 6y agoIt's behind a paywall, but according to a summary [0], Marsalek or someone from Wirecard built fake physical branches of banks on the Philippines. The auditors of EY were invited to come to these branches to talk to actors who convinced them that the 1.9 billion EUR of Wirecard exist on their bank accounts. It reminds me somehow of the movie "The Sting"... [0] https://www.focus.de/finanzen/boerse/wirtschaftsticker/schauspieler-in-der-videokonferenz-ex-wirecard-vorstand-marsalek-das-drehbuch-seines-fast-perfekten-bluffs_id_12340700.html https://www.focus.de/finanzen/boerse/wirtschaftsticker/schau...
- stephenr 6y agoI can’t read German so I don’t know the details the story is detailing if any but isn’t this just the ultimate example of “fake it till you make it”, combined with an Uber-esque disdain for laws and regulations? Why are people always so surprised when “disruptive” organisations actually end up doing a bunch of weird shit?
- jacquesm 6y agoI don't think they ever planned to 'make it'.
- deleted 6y ago[deleted]
- holidayacct 6y agoThis happens all the time, I worked for a company that was audited by a security firm. The security firm compromised every part of the company by pretending to be employees, third party vendors or competitors looking to hire away current employees. Some of their existing employees gave away every single detail you'd need to compromise the infrastructure during interviews. Fooling auditors isn't going to be all that difficult, most auditors get confused if there is too much going on in the room . I've literally seen a publicly traded company pass an audit just by making the audit frustrating and then providing every perk you can imagine outside of the audit room (including attractive men/women). As you can imagine, they didn't do a very thorough audit.
- shallowthought 6y agoThis is the most irritating paywall I've ever seen. Why did you submit this?
- throwaway15516 6y agoI know someone who worked at a well-known Berlin Fintech and once there were people visiting from a partner bank. They expected people in various formal positions there so they filled them in ad-hoc with the available people. I guess audit means most of the time just: checking some boxes without actually following through paper trails.